Skip to main content
NIS2 · PORTUGAL

NIS2 in Portugal — the RJC, MyCiber registration, and a long runway to full measures.

Portugal transposed NIS2 through Decreto-Lei n.º 125/2025 — the Regime Jurídico da Cibersegurança, or RJC — which entered into force on 3 April 2026 and replaced the earlier 2019 framework. The National Cybersecurity Centre (CNCS — Centro Nacional de Cibersegurança) is the single competent authority, with CERT.PT as the national incident-response team. Registration runs through the CNCS MyCiber platform: entities already in scope when the law took effect had 60 working days to register; entities that fall into scope later get 30.

The RJC separates the clocks in a way most transpositions do not. The law and its registration duties are live now, but the full risk-management measures apply only from 22 June 2028, under Regulation 756/2026, in force since 23 June 2026. That makes Portugal one of the longest runways in the Union — and one of the easiest regimes in which to mistake "registered" for "compliant". Fines follow the directive ceilings: up to EUR 10 million or 2% of worldwide turnover for essential entities, EUR 7 million or 1.4% for important ones.

Who it applies to

Essential and important entities across the NIS2 sectors. Registration is through the MyCiber platform — 60 working days for entities in scope at entry into force, 30 days for entities that become subject later. Incident reporting follows the directive standard: 24-hour early warning, 72-hour notification, one-month final report.

The clock

Competent authority: CNCS (Centro Nacional de Cibersegurança). Transposition: Decreto-Lei n.º 125/2025 — Regime Jurídico da Cibersegurança (RJC).

NIS2 in Portugal · timeline
WhenWhat happens
3 Apr 2026RJC (Decreto-Lei n.º 125/2025) enters into force; registration clocks start
23 Jun 2026Regulation 756/2026 enters into force — the detailed measures framework
22 Jun 2028Full risk-management measures apply

Two clocks: register now, comply by 2028

Portugal runs the reverse of the last-minute transpositions: the law arrived late — in force 3 April 2026, well past the EU deadline — but gives entities the longest measures runway in the Union, with full obligations only from 22 June 2028. The trap is symmetrical to Bulgaria's: where Bulgaria compressed everything into day one, Portugal lets a completed registration masquerade as compliance. Filing on MyCiber satisfies the first duty and none of the rest. TruSecure holds the two clocks apart — registration status as a dated fact, and the Regulation 756/2026 measures mapped against the 2028 horizon as the planning spine — so the long runway gets used, not absorbed.

What it asks, in operating terms

Read as an operating requirement rather than a legal text, the Portugal transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.

Portugal requirements · how TruSecure answers them
What the law asksWhere it is answered
Register on MyCiber (60 working days; 30 for new entities)Entity profile · registration facts held as dated records
Implement the Regulation 756/2026 measures by 22 Jun 2028Control library · measures mapped and phased to the deadline
Report incidents: 24 h, 72 h, one monthIncident workflow · clocked from awareness, stages pre-built
Show management responsibility for cybersecurityGovernance workspace · approvals and training records, dated
Keep evidence current across a two-year runwayEvidence automation · drift flagged, not discovered at audit

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

Portugal NIS2 readiness file · excerptSample data
MyCiber registration
filed 22 May 2026 · entity record accepted
Scope basis
essential entity · RJC sector classification recorded
Measures progress
61/96 · phased against the Jun 2028 horizon
Incident reports
0 filed · workflow tested, clocks rehearsed
Export
sealed · sha256:3c9e...a7f1

Compliance roadmap

Typical timeline: 3–6 months to full compliance readiness

  1. 1Weeks 1–4

    Assessment

    Gap analysis against NIS2, risk review, remediation plan.

  2. 2Weeks 5–12

    Implementation

    Controls deployed, policies written, evidence flowing.

  3. 3Weeks 13–16

    Audit prep

    Gaps closed, evidence package assembled for the authority.

  4. 4Weeks 17–24

    Steady state

    Continuous evidence, reports on demand, drift alerts.

With TruSecure: 3× faster to audit-ready. AI does the evidence work; your team keeps the decisions.

Where teams usually start

With a demo walked through by TruSecure — your registration position, the Regulation 756/2026 measures mapped against what you already operate, and a phase plan to the June 2028 horizon. Onboarding produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 (Directive (EU) 2022/2555) is enforced in Portugal by CNCS (Centro Nacional de Cibersegurança). TruSecure determines applicability against Portugal's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacenters. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.

Frequently Asked Questions

When do the full Portuguese security measures actually apply?
Decree-Law 125/2025 has been in force since 3 April 2026 and the registration clocks are already running, but the full risk-management measures — set out in Regulation 756/2026 — apply from 22 June 2028. TruSecure tracks both clocks separately so registration is never mistaken for compliance.